PT-2026-83553 · Dolibarr · Dolibarr
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Dolibarr versions 10.0.0 through 23.0.0
Description
Authenticated users can retrieve group memberships of other users because the software fails to perform per-object authorization checks. By calling the 'GET /users/{id}/groups' API endpoint with arbitrary
id values, an attacker can access group names, entity associations, and private notes across tenant boundaries.Recommendations
Update to version 24.0.0 or later.
Restrict access to the 'GET /users/{id}/groups' API endpoint to minimize the risk of unauthorized data retrieval.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dolibarr